CVE-2020-10457
Severity CVSS v4.0:
Pending analysis
Type:
CWE-22
Path Traversal
Publication date:
12/03/2020
Last modified:
06/10/2022
Description
Path Traversal in admin/imagepaster/image-renaming.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to rename any file on the webserver using a dot-dot-slash sequence (../) via the POST parameter imgName (for the new name) and imgUrl (for the current file to be renamed).
Impact
Base Score 3.x
2.70
Severity 3.x
LOW
Base Score 2.0
4.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:chadhaajay:phpkb:9.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



